Overslaan naar inhoud

Security & Privacy (Expert) - ATRIAS

Customer: ATRIAS Schaarbeek België
Dates: 2026-11-02 — 2028-11-01
Arrangements: 60% work regime; in principle at least two working days per week on site at Atrias in Brussels; broader on-site presence may be requested when reasonably necessary; occasional travel to other Atrias locations or third-party locations may be required; motivated exceptions may be permitted under Atrias policy.
Apply before: 2026-10-01

Description

Atrias is seeking a Security & Privacy Expert for its Security, Privacy & Access team in Brussels. Atrias and its shareholders, the Belgian distribution system operators, are considered an essential entity under NIS2 legislation. Atrias achieved ISO 27001 certification in 2026 and aims to obtain ISO 27701 certification in 2027. The assignment therefore combines privacy, information security and legal expertise in a regulated energy-market environment.

The consultant will integrate and follow up security and privacy requirements in contract management with service providers and in change management. The role also covers optimizing the register of data processing agreements, updating existing agreements where necessary, and updating the record of processing activities including retention periods. The consultant will establish a process for maintaining that register and contribute to the optimization and maintenance of Atrias's ISMS and PIMS. Privacy aspects and general legal support are explicit areas of emphasis.

The assignment is planned from 2 November 2026 until 1 November 2028, with an indicative 270 days per person and a 60% work regime. Services are in principle performed at least two working days per week at Atrias's Brussels office, with broader on-site presence possible when reasonably required and occasional travel to other Atrias or third-party locations. The profile requires substantial legal, security, privacy, data-governance and ISO experience, plus C1 language capability. Experience in the Belgian energy market and agile project work is preferred.

Top Reasons to Apply
ISO 27701 journey
★★★★★
Energy market impact
★★★★★
Privacy security blend
★★★★★
Strategic legal exposure
★★★★★
Hybrid working model
★★★★★
Responsibilities
Integrate contract security requirements
Integrate change security requirements
Optimize processing agreement register
Update existing processing agreements
Update processing activity register
Create register maintenance process
Optimize Atrias ISMS PIMS
Maintain Atrias ISMS PIMS
Must Have
Privacy management experience
Privacy legal expertise
Security consulting expertise
Data governance experience
ISO standards implementation
Security contract drafting
DPIA risk analysis
Processing register experience
Nice to Have
Belgian energy experience
Agile project experience

Detailed Responsibilities and Skills

Additional Responsibilities

  • Provide general legal support
  • Address privacy task aspects

General skills

  • Demonstrable company experience in privacy management (DPO certification); note: the vacancy explicitly states DPO certification is not mandatory for this request.
  • 8 years demonstrable experience as a legal expert in privacy and information security, at expert level.
  • Master's degree in Law.
  • Supplier must attach a document describing how the candidate can call on external support outside Atrias if needed.
  • Candidate must demonstrate sufficient communication skills during a possible interview for collaboration within multidisciplinary teams.
  • Candidate must demonstrate during a possible interview that they can work independently and proactively.
  • English, Dutch and French at European CEFR C1 level.
  • Dutch or French at European CEFR C1 level.
  • Preferred: Demonstrable experience within the Belgian energy market.
  • Preferred: Demonstrable experience working in agile projects.

Technical skills

  • 8 years demonstrable experience as a Security Consultant in at least one of these environments: data, infrastructure, applications, or similar, at expert level.
  • Demonstrable experience in data governance, including data classification, data retention and data transfer, including in cloud environments.
  • Demonstrable experience implementing ISO 27001, ISO 27002 and ISO 27701.
  • Demonstrable experience drafting contracts with service providers and customers, specifically covering information security and privacy aspects.
  • Demonstrable experience developing DPIAs and risk analyses.
  • Demonstrable experience with records of processing activities and registers of data processing agreements.
  • Demonstrable knowledge and experience in Information Security Management (ISO 2700x).
  • Demonstrable knowledge of Belgian privacy legislation and GDPR.

Tools

  • Experience contributing to the optimization and maintenance of an Information Security Management System (ISMS).
  • Experience contributing to the optimization and maintenance of a Privacy Information Management System (PIMS).